Home/Services/Risk Advisory

Risk advisory.

Internal audit, internal financial controls and IT systems reviews that test whether governance and processes hold up under scrutiny — not just whether a policy exists on paper.

Internal audit

Process-cycle reviews, not a generic checklist

Internal audit scoped around how the business actually operates — the cycles where risk concentrates, not a template applied uniformly regardless of what the company does.

01

Procure-to-pay

Vendor selection and master-data controls, purchase-requisition approval, three-way match (invoice, PO, receipt), and payment approval and authorisation.

02

Order-to-cash

Customer master and order-entry controls, invoice generation accuracy, segregation of duties, and order-approval workflow including credit checks.

03

Fixed assets & capex

Approval and authorisation for acquisitions, physical verification and tagging, disposal processes, and ITC applicability on additions.

04

Inventory & production

Inventory records and movement reports, sample-based physical verification, valuation review, and — where relevant — production-process and quality-standard walkthroughs.

05

Payroll & treasury

Hiring and attendance-tracking controls, statutory compliance (PF/ESI/gratuity), treasury policy review, cash-flow forecasting and bank reconciliation.

06

Statutory compliance & financial reporting

GSTR-2A reconciliation with books, TDS compliance, and review of the month-end/year-end financial close process.

Internal financial controls

IFC / ICFR evaluation

Entity-level controls and process-level Risk & Control Matrices, evaluated across the cycles where financial reporting risk actually sits.

Order-to-cash

Procure-to-pay

Inventory & manufacturing

Fixed assets & capex

Payroll & employee costs

Treasury, forex & related parties

Financial close & reporting

IT general controls

What increases risk exposure

Six patterns we look for first

Recurring gaps we assess for, drawn from our internal-audit and IFC engagement experience.

Culture & risk awareness

Risk awareness not consistently embedded across management and staff, allowing lapses to go unnoticed.

IT general controls

Gaps in access management, change management and system configuration exposing key systems to error or unauthorised access.

Maker-checker controls

Secondary review not consistently applied across critical transaction cycles.

Segregation of duties

Overlapping roles and unclear delegation of authority increasing exposure to unchecked transactions.

Policies & documentation

Absence of formally documented SOPs and delegation-of-power matrices creating inconsistent execution.

Fraud monitoring

Limited ability to proactively detect anomalies or irregular transactions without continuous monitoring.

Also within Risk Advisory

Beyond process audits

·

ITGC / ITAC

Assessment of ERP systems, IT infrastructure, cyber security and IT general/application controls.

·

Fixed asset verification

Comprehensive physical verification, reconciliation with registers, and obsolescence assessment; inventory verification and costing review, including physical stock observation.

·

Forensic audit

Detection of fraud, misappropriation and misconduct, including digital forensics where required.

Contact

For queries relating to internal audit, IFC/ICFR or risk advisory, please get in touch.